This thread's last reply is from February 9, 2010, 3:46 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Hi Jmak.
Things look good so far, please continue with the instructions below.
Disable Windows Defender
- Go to Start > All Programs > Windows Defender.
- Click on Tools at the top.
- Under Settings, click on Options.
- Under Automatic scanning, uncheck (untick) Automatically scan my computer (recommended) box.
- Under Real-time protection options, uncheck (untick) Use real-time protection (recommended) box.
- Click on the Save button at the bottom right hand corner.
- Note: Please do not Re-enabling this until i tell you to do so.
Next.
Download and run OTM
Download [url=http://oldtimer.geekstogo.com/OTM.exe:1ta5ncfw]
OTM by
Old Timer and save it to your Desktop.
No more redirecting, performance is great, as if there were no malware on my computer
All processes killed
========== PROCESSES ==========
========== FILES ==========
c:\users\[redacted]\AppData\Roaming\PnkBstrK.sys moved successfully.
c:\windows\system32\PnkBstrB.exe moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1154355 bytes
->FireFox cache emptied: 3063142 bytes
User: IUSR_NMPR
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: jason
->Temp folder emptied: 0 bytes
User: [redacted]
->Temp folder emptied: 2332386 bytes
->Temporary Internet Files folder emptied: 3705286 bytes
->Java cache emptied: 72833439 bytes
->FireFox cache emptied: 37840422 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 554936 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 34231760 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 25537799 bytes
RecycleBin emptied: 3845286 bytes
Total Files Cleaned = 177.00 mb
OTM by OldTimer - Version 3.1.8.0 log created on 02062010_021303
Files moved on Reboot...
C:\Users\[redacted]\AppData\Local\Temp\VGXF4E8.tmp moved successfully.
C:\Windows\temp\08adc074-c018-4a31-b377-3fe042bf0cc6.tmp moved successfully.
C:\Windows\temp\08eff2b4-3da6-40d1-80c9-dffdb7bac947.tmp moved successfully.
C:\Windows\temp\0c0deb5f-cc57-4450-93f5-786629668e2a.tmp moved successfully.
C:\Windows\temp\0e18bcbb-6719-484c-89f2-0bb15948bbd1.tmp moved successfully.
C:\Windows\temp\17032442-dce1-48e1-991b-06a12c284cc4.tmp moved successfully.
C:\Windows\temp\1d30a46d-19ad-45a4-922b-a2255452a8ea.tmp moved successfully.
C:\Windows\temp\21f0deb4-3db1-4eaf-a147-97d28e3ef52b.tmp moved successfully.
C:\Windows\temp\24567a13-ab6e-41b3-bf11-686eaeab6b32.tmp moved successfully.
C:\Windows\temp\280a3243-a434-4e7d-bae8-e4cbb1a0a028.tmp moved successfully.
C:\Windows\temp\307d1541-9404-4b40-963f-71c7b701ffde.tmp moved successfully.
C:\Windows\temp\36937da9-99e4-43b2-8c1b-cb98c6e73621.tmp moved successfully.
C:\Windows\temp\4a2c1a03-dc82-4ec4-a6c4-8c7f7517d328.tmp moved successfully.
C:\Windows\temp\52dd9800-eee2-4024-aced-cfa987df719a.tmp moved successfully.
C:\Windows\temp\53a01cb0-473c-424f-9de4-6512ee64d440.tmp moved successfully.
C:\Windows\temp\56e7aaed-af34-46ab-8b24-a18208662843.tmp moved successfully.
C:\Windows\temp\58417dd5-d917-4d68-b489-52cc09c4ed53.tmp moved successfully.
C:\Windows\temp\6aa222da-faf0-4415-a596-151979439a25.tmp moved successfully.
C:\Windows\temp\6b3b9695-121c-4149-a97c-dc24c27ac9e3.tmp moved successfully.
C:\Windows\temp\7df0b286-716d-4ff7-a400-b5688d4fa443.tmp moved successfully.
C:\Windows\temp\83ab3b63-927f-4f9a-a65b-5ee0e899def6.tmp moved successfully.
C:\Windows\temp\86546b90-122e-46c7-b628-030a62825a1f.tmp moved successfully.
C:\Windows\temp\8b302646-cea9-44f2-8692-89ff7aa2d3f1.tmp moved successfully.
C:\Windows\temp\8ede853a-d2ce-4cc0-bc60-19ad65d6e7f1.tmp moved successfully.
C:\Windows\temp\9f439070-2ae1-4c17-af9f-9593aa20c335.tmp moved successfully.
C:\Windows\temp\a2f078b3-f7ff-4e0a-9d50-5e6f01ad6c16.tmp moved successfully.
C:\Windows\temp\a388e88e-7c88-40e2-9e83-7cca647b34fe.tmp moved successfully.
C:\Windows\temp\ae27c5ff-8116-44b5-96f8-ef23a86832eb.tmp moved successfully.
C:\Windows\temp\c8692aab-cda6-4cf6-987e-d9552902ea8c.tmp moved successfully.
C:\Windows\temp\ca606e04-7343-476f-aaf4-d9cf6ebf2bf9.tmp moved successfully.
C:\Windows\temp\ce57cc2b-0601-4d96-b2f8-47255fa5a80f.tmp moved successfully.
C:\Windows\temp\dd0ca5dc-e3b5-4e9a-92b2-a7807ce0daf1.tmp moved successfully.
C:\Windows\temp\e69fe628-ce89-447e-bcb2-b0458a9afc93.tmp moved successfully.
C:\Windows\temp\e7c9e3c2-4f1a-4406-ba76-f0e58bfea424.tmp moved successfully.
C:\Windows\temp\ea1ce795-cb19-416f-b727-6a97a183cb56.tmp moved successfully.
C:\Windows\temp\ef5a293a-7a93-4781-a06d-7d15e2ede94d.tmp moved successfully.
C:\Windows\temp\f5b52ec5-69f5-4bbc-8e28-5f183d8f4747.tmp moved successfully.
C:\Windows\temp\fcea808b-344f-4cb7-a367-b46f8cba5119.tmp moved successfully.
C:\Windows\temp\fe50e5f2-19ad-4729-a057-4cd1c93dfae6.tmp moved successfully.
File move failed. C:\Windows\temp\nmsmc_DQLWinService.log scheduled to be moved on reboot.
Registry entries deleted on Reboot...
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=f2f818faa96c6a4392bdc67952ac0a4e
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-02-07 12:41:31
# local_time=2010-02-07 04:41:31 (-0800, Pacific Standard Time)
# country="Canada"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 2634238 2634238 0 0
# compatibility_mode=1029 16777213 100 91 131514 2798324 0 0
# compatibility_mode=1280 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776574 100 100 1157693 102147970 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=198117
# found=2
# cleaned=0
# scan_time=6049
C:\Qoobox\Quarantine\C\Windows\System32\0.vir a variant of Win32/Kryptik.CCM trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Windows\System32\_sdra64_.exe.zip a variant of Win32/Kryptik.CCM trojan 00000000000000000000000000000000 I
Hi Jmak your latest set of logs appear to be clean!
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
Time for some housekeeping
- Click on Start >> Run...
- Now type in ComboFix /Uninstall into the and click OK.
- Note the space between the X and the /Uninstall, it needs to be there.

The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.
Next.
Clean up with OTM
- Double-click OTM.exe to start the program, This tool will remove all the tools we used to clean your pc.
- Close all other programs apart from OTMoveIt3 as this step will require a reboot
- On the OTM main screen, press the CleanUp! button
- Say Yes to the prompt and then allow the program to reboot your computer.
You can now delete any tools we used that remain on your Desktop.
Protection Programs
Don't forget to
re-enable any protection programs we disabled during your fix.
Now we needed to deal with security vulnerabilities
Update Firefox
- Your version of Firefox is outdated.
- In the Firefox browser click Help > Check for updates to install the latest version.
Here are some free programs I recommend that could help you improve your computer's security.
Install Sitehound
SiteHound is a toolbar for Microsoft Internet Explorer and Mozilla Firefox which alerts you if you're about to enter a potentially dangerous website.
You can find more information and download it from
Here
Install WinPatrol
As a robust security monitor,
WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.
For more information, please visit
HERE
MVPS Hosts
Install MVPS Hosts File From Here
The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer.
You can Find the Tutorial HERE
Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
You can use one of these sites to check if any updates are needed for your pc.
Secunia Software Inspector
F-secure Health Check
Microsoft Windows Update
Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Install the updates immediately if they are found.
To update Windows
Go to
Start >
All Programs >
Windows Update >
Check for updates.
To update Office
Open up any Office program.
Go to
Help >
Check for Updates
Read some information HERE On how to prevent Malware
Is your pc running slow?
Read
What to do if your Computer is running slowly
I would be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Safe surfing!
Once again, thank you for helping me remove malware.

you are the best!
Hi Jmak.
You are most welcome
I will ask for this topic to be closed good luck.
As this issue appears to be resolved,